Security Ninja PRO v5.303 Plugin

Security Ninja PRO is a comprehensive WordPress security plugin built on years of industry best practices to help protect your website from vulnerabilities and attacks. It performs over 40 security tests, including checks for brute-force exposure and known weaknesses such as the Timthumb vulnerability. The plugin scans your site for potential security holes and provides preventive measures to reduce risk. With detailed explanations and included code snippets for quick fixes, it makes strengthening your site’s security straightforward and practical.
Security Ninja PRO works through dedicated modules that continuously monitor and analyze your WordPress installation. The Core Scanner compares your core files with official master copies from WordPress.org to detect unauthorized changes, while the Malware Scanner checks themes and plugins for malicious code. An Events Logger records site activity, including failed login attempts, and the Scheduled Scanner runs automated tests without manual intervention. Together, these tools provide ongoing monitoring and proactive protection for your website.
Core Features of Security Ninja PRO Plugin
- 40+ Security Tests: Performs over 40 tests including brute-force attack checks.
- Vulnerability Detection: Scans your site for security weaknesses and holes.
- Timthumb Vulnerability Check: Detects exposure to the Timthumb vulnerability.
- Preventive Security Measures: Provides tools to help prevent attacks.
- Quick Fix Code Snippets: Includes ready-to-use code snippets for fast security improvements.
- Core Scanner Module: Compares WordPress core files with official master copies.
- Malware Scanner Module: Scans theme and plugin files for malicious code.
- Events Logger Module: Logs site events including failed login attempts.
- Scheduled Scanner Module: Runs automated security tests on a schedule.
What’s New (Changelog) in Security Ninja PRO v5.303
= 5.303 =
* 2026-09-08
* NEW: Visitor IP detection - Choose how the firewall reads the visitor IP: Automatic, Cloudflare, proxy headers, or REMOTE_ADDR. Automatic trusts Cloudflare ranges by default. For another load balancer or reverse proxy, add its IPs under Trusted proxy CIDRs. Free and Pro.
* IMPROVED: Vulnerability Scanner - Scheduled warning emails wait for a finished scan, skip plugins and themes that are gone or already patched, and do not repeat the same findings within 24 hours. Thank you Jamie.
* IMPROVED: Deactivation - One central "Remove settings when deactivating" switch. Leave it off to keep settings, scans, logs, and cached files. Scheduled jobs still stop when the plugin is deactivated.
* IMPROVED: Uninstall - Removing the plugin also clears module tables, settings, cached files, and related user metadata.
* IMPROVED: Events Logger - Administrator emails now cover new accounts and role promotions.
* IMPROVED: Events Logger - Speed improvement - When logging is off, event hooks and database writes are skipped. Broad REST API error logging stays off by default; turn it on in Events settings if you need those diagnostics.
* IMPROVED: Settings import/export and MainWP - Events REST logging and visitor IP settings, including trusted proxy CIDRs, are included when you copy settings between sites.
* IMPROVED: Malware Scanner - Removed the unused legacy scanner.
* IMPROVED: MainWP - Applying settings remotely now reschedules the scanner cron when the schedule changes, and applies the same wp-config updates as the Fixes page (file editor, debug, secure cookies).
* IMPROVED: MainWP - Remote settings now include WooCommerce rate-limit numbers, 2FA grace period and login copy, and satellite/ASN soft-mode lists.
* IMPROVED: Frontend - Speed improvement - Premium no longer loads unused Pro modules on public page views. Free modules are unchanged. Thank you Jose.
Similar Plugins

